Retail Relay home

Data processing terms

Retail Relay Data Processing Addendum

Updated August 2, 2026Version 2026-08-02-private-test-draftDownload a copy
Contents
  1. 1. Definitions and interpretation
  2. 2. Roles, scope, and documented instructions
  3. 3. Use restrictions
  4. 4. Personnel and confidentiality
  5. 5. Security measures
  6. 6. Subprocessors
  7. 7. Individual rights and compliance assistance
  8. 8. Security incidents
  9. 9. Government and third-party demands
  10. 10. Data location and restricted transfers
  11. 11. Return and deletion
  12. 12. Information and audits
  13. 13. Term, conflict, and governing terms
  14. Annex 1 — Processing details
  15. Annex 2 — Current technical and organizational measures
  16. Annex 3 — Subprocessors
  17. Execution requirement
Related documentsTermsPrivacyDPASubprocessorsCancellation

Review draft — not automatically effective

This DPA is published for review during the attended private test. Viewing it, creating an account, or accepting the Terms does not by itself execute this DPA. It becomes effective only when Putnam Development Studios LLC and the customer expressly sign it or an Order Form expressly incorporates this exact version after required contact, retention, and transfer details are completed.

Public-launch configuration remains incomplete: public legal-notice email, public privacy email, public support email, approved data-retention schedule, verified Stripe cancellation configuration.

This Data Processing Addendum (“DPA”) is proposed between Putnam Development Studios LLC (“Retail Relay,” “Processor,” “Service Provider,” “we,” or “us”) and the customer legal entity identified in an Order Form or other written acceptance (“Customer,” “Controller,” or “Business”). It supplements the Retail Relay Terms of Service or other agreement that expressly incorporates it (the “Agreement”).

This DPA applies only to Personal Data that Retail Relay processes on Customer’s behalf to provide the Service (“Customer Personal Data”). It does not govern information for which Retail Relay independently determines the purposes and means of processing, such as its own account-security, billing, fraud-prevention, and legal-compliance records, except where applicable law provides otherwise.

1. Definitions and interpretation

“Applicable Data Protection Law” means a privacy or data-protection law that applies to Customer Personal Data and the relevant party’s processing under the Agreement. “Controller,” “Processor,” “Business,” “Service Provider,” “Sell,” “Share,” “Personal Data,” and “Personal Information” have the meanings given by Applicable Data Protection Law. “Subprocessor” means a third party engaged by Retail Relay to process Customer Personal Data on Customer’s behalf. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, excluding unsuccessful attempts that do not compromise Customer Personal Data.

If terminology differs among applicable laws, this DPA will be interpreted to preserve substantially equivalent controller-to-processor or business-to-service-provider protections. References to written instructions include exact configuration, prompts, connected-account authorization, reviewed plans, and other use of the Service consistent with the Agreement; they do not include instructions embedded in untrusted uploaded or source-system text.

2. Roles, scope, and documented instructions

Customer determines the purposes of processing Customer Personal Data and is the Controller or Business. Retail Relay acts as Processor or Service Provider and will process Customer Personal Data only to provide, secure, support, and troubleshoot the Service; carry out Customer’s documented instructions; comply with law; and perform the activities in Annex 1. Customer instructs Retail Relay to use the Subprocessors on the published Subprocessor List for those purposes.

Retail Relay will notify Customer if it reasonably believes an instruction violates Applicable Data Protection Law, unless law prohibits notice, and may pause the affected processing while the parties resolve the issue. Customer is responsible for the lawfulness, accuracy, and scope of its instructions; its notices and lawful bases; the authority of its users; and avoiding unsupported sensitive or regulated data.

3. Use restrictions

  • Retail Relay will not Sell or Share Customer Personal Data, as those terms are defined by applicable U.S. state privacy law, or use it for cross-context behavioral advertising.
  • Retail Relay will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the business purposes stated in the Agreement and this DPA, except as permitted or required by law.
  • Retail Relay will not combine Customer Personal Data with personal information received from another person or collected from its own consumer interactions except where Applicable Data Protection Law permits a service provider or processor to do so.
  • Retail Relay will not use Customer Personal Data to train a generalized model for other customers unless Customer separately and expressly opts in through a written or comparably clear agreement.

The parties acknowledge and agree that Customer makes Customer Personal Data available to Retail Relay only for the limited and specified purposes in the Agreement and this DPA. Retail Relay certifies that, once this DPA is effective, it understands and will comply with the restrictions in this Section.

4. Personnel and confidentiality

Retail Relay will limit access to Customer Personal Data to personnel and contractors who need access to perform the Agreement, ensure they are bound by appropriate confidentiality obligations, and provide privacy and security instruction appropriate to their responsibilities. Customer will restrict its own user access and promptly remove personnel who no longer require access.

5. Security measures

Retail Relay will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature and risk of Customer Personal Data. The current measures are summarized in Annex 2. The parties acknowledge that the Service is under attended private test and no internet-connected system is completely secure.

Customer is responsible for securing its endpoints and source accounts, using least-privilege roles, maintaining source-system backups and reconciliation procedures, reviewing exact plans before approval, and promptly disabling access or activating available kill switches when compromise or error is suspected.

6. Subprocessors

Customer gives general authorization for the Subprocessors identified on the public Subprocessor List. Retail Relay will contractually require each Subprocessor to protect Customer Personal Data to a standard appropriate to its services and Applicable Data Protection Law, and remains responsible for Subprocessor performance to the extent required by law and the Agreement.

During the attended private test, Retail Relay will provide notice of a materially new Subprocessor through the established direct operator channel before sending private-test Customer Personal Data to it where reasonably practicable. A durable public notice and objection process must be configured before broader enrollment. If Customer reasonably objects on documented data-protection grounds, the parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected feature or Service.

7. Individual rights and compliance assistance

Taking into account the nature of processing and information available to Retail Relay, Retail Relay will provide reasonable assistance for Customer to respond to verified individual-rights requests, data-protection impact assessments, regulator consultations, and other processor-assistance duties required by Applicable Data Protection Law. If Retail Relay receives a request concerning Customer Personal Data, it will refer the requester to Customer where legally permitted and will not independently respond on Customer’s behalf unless instructed or legally required.

Customer remains responsible for determining whether a request is valid, verifying the requester, identifying applicable exceptions, and giving lawful instructions. Assistance beyond normal product functionality may be subject to reasonable fees where permitted by law and agreed in advance.

8. Security incidents

Retail Relay will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and will provide information reasonably available to help Customer meet applicable notification duties. Notice does not admit fault or liability. Retail Relay may provide information in phases as investigation proceeds and may withhold information where disclosure would create a security risk or violate law.

During the attended private test, incident coordination uses the established direct operator channel. A dedicated security or legal notice address and a tested escalation procedure must be configured before broader enrollment.

9. Government and third-party demands

Unless prohibited by law, Retail Relay will notify Customer of a legally binding demand for Customer Personal Data and provide reasonable information so Customer may seek protection. Retail Relay will challenge demands that it reasonably believes are unlawful or overbroad when a challenge is legally available and proportionate, and will disclose only information it is legally required to disclose.

10. Data location and restricted transfers

The current Service uses U.S.-based and globally operated cloud providers and may involve remote processing. This draft does not itself add Standard Contractual Clauses, a United Kingdom addendum, or another restricted-transfer mechanism. A customer that requires one must not submit covered Customer Personal Data until the parties execute the required transfer terms and confirm the relevant service configuration.

11. Return and deletion

At the end of the Service, Retail Relay will, at Customer’s choice and subject to product functionality, return or delete Customer Personal Data when no longer reasonably needed to provide the Service, except where law or documented billing, security, dispute, backup, source-operation reconciliation, legal-acceptance, or audit requirements permit or require retention. Retained data remains protected by this DPA for as long as it is Customer Personal Data.

No fixed return window or record-by-record deletion period is promised in this private-test draft because the retention schedule is not yet approved or implemented. Customer must maintain its own authoritative source records and exports. A final retention and deletion schedule is a prerequisite to making this DPA available for broader enrollment.

12. Information and audits

Retail Relay will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to confidentiality, security, and third-party restrictions. If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request a narrowly scoped audit by an independent qualified auditor no more than once annually, except after a material Security Incident or regulator request. The audit must avoid access to other customers’ data and unreasonable disruption, and Customer bears reasonable costs unless the audit identifies material noncompliance by Retail Relay.

13. Term, conflict, and governing terms

Once effective, this DPA continues while Retail Relay processes Customer Personal Data on Customer’s behalf. It controls over the Agreement only for a conflict about that processing. The Agreement’s liability terms apply to this DPA to the extent permitted by Applicable Data Protection Law. Unless a signed Order Form provides otherwise, the laws of the State of Maine govern and exclusive venue lies in the state and federal courts serving Cumberland County, Maine.

Annex 1 — Processing details

  • Subject matter: provision of the Retail Relay business-to-business R-Series synchronization, analysis, reporting, document-processing, alerting, billing-support, and separately approved operational workflows.
  • Duration: the term of the Agreement plus the limited retention described in Section 11.
  • Nature and purposes: hosting, organizing, synchronizing, retrieving, comparing, extracting, classifying, calculating, presenting, securing, supporting, and—only after separate exact-plan approval—transmitting typed operations and verifying results.
  • Data subjects: Customer’s authorized users, personnel represented in business records, supplier and Vendor contacts, and other people whose business information Customer lawfully places in connected R-Series records or procurement documents.
  • Data categories: account identifiers and business contact details; organization membership and roles; source-system account, Shop, Item, ItemShop, inventory, Vendor, order, sale, and related evidence; prompts and documents; product and Vendor mappings; plans, approvals, verification and audit evidence; billing metadata; and technical security data.
  • Sensitive data: not intentionally supported. Customer must not submit payment-card data, government identifiers, health, biometric, children’s, or other specially regulated information unless a later written agreement and product feature expressly support it.
  • Processing frequency: as initiated by authorized users, scheduled bounded workers, connection synchronization, and billing or security events during the Service term.

Annex 2 — Current technical and organizational measures

  • Authentication and authorization derived from verified sessions, with organization and connection scope enforced on data and source operations.
  • Independently encrypted R-Series OAuth token sets and refresh coordination for each connection; credentials and raw secrets excluded from model-visible output and ordinary logs.
  • Default read-only source transport and exact method, account-bound path, connection, operation, execution, and capability allowlists for any approved write.
  • Typed operations, immutable plans, policy checks, trusted human review, server-bound approvals, durable queues, kill switches, pre-dispatch revalidation, ambiguity reconciliation, exact read-back verification, and append-only audit evidence.
  • Tenant-scoped managed database access, signed billing webhooks, server-derived billing quantities, bounded file and request sizes, conservative API rate limiting, and source-origin validation.
  • Service-provider access limited to operational need, with provider contractual and security controls applicable to Vercel, Supabase, OpenAI, and Stripe.
  • Operational incident investigation, dependency updates, backups and recovery measures provided by the managed infrastructure and application procedures, subject to private-test limitations documented in the Service.

Annex 3 — Subprocessors

The current authorized Subprocessors and their service functions are listed at https://www.retailrelayai.com/subprocessors. Customer-directed Lightspeed R-Series connections are separately identified there and are not characterized as Retail Relay-selected Subprocessors.

Execution requirement

This draft has no signature block, online DPA-assent mechanism, or completed public notice channel. It must not be represented as executed or automatically binding. If the parties need a DPA for the attended private test, they must identify the Customer legal entity, complete any required transfer or jurisdiction supplements, and expressly sign or incorporate this exact version in an Order Form.

Service provider: Putnam Development Studios LLC, a Maine limited liability company that provides the Service under the Retail Relay brand.

Legal: not yet published for the attended private test

Privacy: not yet published for the attended private test

Support: not yet published for the attended private test